Chapter 1: Security & Risk Management Flashcards

1
Q

Define Confidentiality

A

The principle that objects are not disclosed to unauthorized subjects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define Integrity

A

The principle that objects retain their veracity and are intentionally modified only by authorized subjects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define Availability

A

The principle that authorized subjects are granted timely and uninterrupted access to objects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are AAA Services

A

Identification, Authentication, Authorization, Auditing, and Accountability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Identification is the process by which…

A

A subject professes an identity, and Accountability is initiated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Authentication is the process of…

A

Verifying or testing that a claimed identity is valid.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The process of Authorization ensures…

A

That the requested activity or object access is possible given the rights and privileges assigned to the authenticated identity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Auditing is the means by which…

A

Subjects are held accountable for their actions (while authenticated on a system).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Auditing is the means by which…

A

Subjects are held accountable for their actions (while authenticated on a system).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

CISSP stands for…

A

Certified Information Systems Security Professional

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Non-repudiation ensures that…

A

The subject of an activity or event cannot deny the event occurred or their role in the event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Non-repudiation ensures that…

A

The subject of an activity or event cannot deny the event occurred or their role in the event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Security Governance is…

A

The collection of practices related to supporting, defining, and directing the security efforts of an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the 3 types of plans in Security Management?

A

Strategic, Tactical, and Operational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the Primary Security Roles?

A

Senior Manager, Security Professional, Asset Owner, Custodian, User, and Auditor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is COBIT ?

A

Control Objectives for Information and related Technology

17
Q

What is SCRM?

A

Supply Chain Risk Management